An organization allows employees to use mobile devices for business purposes.
Which of the following could cause decreased employee productivity in case of data loss?
How do data analysis technologies affect internal audit testing?
During which phase of the contacting process ate contracts drafted for a proposed business activity?
An organization has a total asset turnover of 3.0 times and a total debt-to-total assets ratio of 80 percent. If the organization has total debt of $1 000 000 what is the organization's sales level?
Which of the following is a project planning methodology that involves a complex series ot required simulations to provide information about schedule risk?
An organization has an agreement with a third-party vendor to have a fully operational facility, duplicate of the original site and configured to the organization's needs, in order to quickly recover operational
capability in the event of a disaster.
Which of the following best describes this approach to disaster recovery planning?
An organization suffered significant damage to its local file and application servers as a result of a hurricane. Fortunately, the organization was able to recover all information backed up by its overseas third-party contractor.
Which of the following approaches has been used by the organization?
What is the most significant potential problem introduced by just-in-time inventory systems?
Which of the following activities best illustrates a user's authentication control?
Which of me following statements is true regarding the reporting of tangible and intangible assets?
Which of the following statements is true regarding partnership liquidation?
A small software development firm designs and produces custom applications for businesses. The application development team consists of employees from multiple departments who all report to a single project manager.
Which of the following organizational structures does this situation represent?
Which of the following types of data analytics would be used by a hospital to determine which patients are likely to require readmittance for additional treatment?
An organization invests excess snort-term cash in trading securities. When of the following actions should an internal auditor take to test the valuation of those securities?
What would an internal auditor do to ensure that a process to mitigate risk is in place for the organization's change management process?
An internal auditor has been approved lo gather data directly horn the organization's relational database management system tor data analyses To collect the data which of the Wowing is most important for the auditor to know?
While reviewing the contracts for a large city, the internal auditor learns that the organization contracted to perform trash collection is paid based on the number of bins emptied each week as a result, the city has minimal control over payments Which of the following actions should the auditor recommend to give the city greater control over payments?
Which of the following application controls checks the integrity of data entered into a business application?
Which of the following IT-related activities is most commonly performed by the second line of defense?
While auditing an organization's customer call center, an internal auditor notices that key performance indicators show a positive trend despite the fact that there have been increasing customer complaints over the same period Which of the following audit recommendations would most likely correct the cause of this inconsistency?
A large hospital has an existing contract with a vendor in another country to provide software support and maintenance of the hospital's patient records information system. From the hospital management's perspective, which of the following controls would be most effective to address privacy risks related to this outsourcing arrangement?
Which component of an organization's cybersecurity risk assessment framework would allow management to implement user controls based on a user's role?
A clothing company sells shirts for $8 per shirt. In order to break even, the company must sell 25,000 shirts. Actual sales total $300,000.
What is margin of safety sales for the company?
According to MA guidance, which of the following would indicate poor change management control?
1) Low change success rate
2) Occasional planned outages
3) Low number of emergency changes.
4) Instances of unauthorized changes
During disaster recovery planning, the organization established a recovery point objective. Which of the following best describes this concept?
Based on lest results an IT auditor concluded that the organization would suffer unacceptable toss of data if there was a disaster at its data center. Which of the following test results would likely lead the auditor to this conclusion?
Which of the following cybersecurity-related activities is most likely to be performed by the second line of defense?
An internal auditor was asked to review an equal equity partnership In one sampled transaction Partner A transferred equipment into the partnership with a self-declared value of $10,000 and Partner B contributed equipment with a self-declared value of $15 000 The capital accounts of each partner were subsequently credited with S12,500. Which of the following statements is true regarding this transaction?
The board of directors wants to implement an incentive program for senior management that is specifically tied to the long-term health of the organization.
Which of the following methods of compensation would be best to achieve this goal?
Which of the following authentication controls combines what a user knows with the unique characteristics of the user respectively?
Which of me Wowing summarizes information about the cash receipts and cash payments for a specific time period?
Which of the following IT controls includes protection for mainframe computers and workstations?
Which of the following describes the most appropriate set of tests for auditing a workstation's logical access controls?
Which of the following is a likely result of outsourcing?
Which of the following organization structures would most likely be able to cope with rapid changes and uncertainties?
A bond that matures after one year has a face value of $250,000 and a coupon of $30,000. If the market price of the bond is $265,000, which of the following would be the market interest rate?
Which of the following security controls would provide the most efficient and effective authentication for customers to access their online shopping account?
What are the objectives of governance as defined by the Standards?
When auditing an application change control process, which of the following procedures should be included in the scope of the audit?
1) Ensure system change requests are formally initiated, documented, and approved.
2) Ensure processes are in place to prevent emergency changes from taking place.
3) Ensure changes are adequately tested before being placed into the production environment.
4) Evaluate whether the procedures for program change management are adequate.
Which of the following would best prevent unauthorized external changes to an organization's data?
Which of the following are typical responsibilities for operational management within a risk management program?
1) Implementing corrective actions to address process deficiencies.
2) Identifying shifts in the organization's risk management environment.
3)( Providing guidance and training on risk management processes.
4) Assessing the impact of mitigation strategies and activities.
Within an enterprise, IT governance relates to the:
1) Alignment between the enterprise's IT long term plan and the organization's objectives.
2) Organizational structures of the company that are designed to ensure that IT supports the organization's strategies and objectives.
3) Operational plans established to support the IT strategies and objectives.
4) Role of the company's leadership in ensuring IT supports the organization's strategies and objectives.
Under a value-added taxing system:
Organizations use matrix management to accomplish which of the following?
The economic order quantity for inventory is higher for an organization that has:
Capacity overbuilding is most likely to occur when management is focused on which of the following?
Which of the following is a major advantage of decentralized organizations, compared to centralized organizations?
Which of the following statements is true regarding the use of public key encryption to secure data while it is being transmitted across a network?
Which of the following describes the result if an organization records merchandise as a purchase, but fails to include it in the closing inventory count?
Which stage of group development is characterized by a decrease in conflict and hostility among group members and an increase in cohesiveness?
Which of the following descriptions of the internal control system are indicators that risks are managed effectively?
1) Existing controls promote compliance with applicable laws and regulations.
2) The control environment is designed to address all identified risks to the organization.
3) Key controls for significant risks to the organization remain consistent over time.
4) Monitoring systems are in place to alert management to unexpected events.
Which of the following is not a method for implementing a new application system?
Which of the following conditions could lead an organization to enter into a new business through internal development rather than through acquisition?
Which of the following is not a potential area of concern when an internal auditor places reliance on spreadsheets developed by users?
In creating a risk-based plan, which of the following best describes a top-down approach to understanding business processes?
The decision to implement enhanced failure detection and back-up systems to improve data integrity is an example of which risk response?
Maintenance cost at a hospital was observed to increase as activity level increased. The following data was gathered:
Activity Level -
Maintenance Cost
Month
Patient Days
January
5,600
$7,900
February
7,100
$8,500
March
5,000
$7,400
April
6,500
$8,200
May
7,300
$9,100
June
8,000
$9,800
If the cost of maintenance is expressed in an equation, what is the independent variable for this data?
Which of the following standards would be most useful in evaluating the performance of a customer-service group?
In order to provide useful information for an organization's risk management decisions, which of the following factors is least important to assess?
Which of the following costs would be incurred in an inventory stockout?
Which of the following statements about slack time and milestones are true?
1) Slack time represents the amount of time a task may be delayed without delaying the entire project.
2) A milestone is a moment in time that marks the completion of the project's major deliverables.
3) Slack time allows the project manager to move resources from one task to another to ensure that the project is finished on time.
4) A milestone requires resource allocation and needs time to be completed.
Which of the following corporate social responsibility strategies is likely to be most effective in minimizing confrontations with influential activists and lobbyists?
Which of the following factors is considered a disadvantage of vertical integration?
Which of the following statements regarding organizational governance is not correct?
Where complex problems need to be addressed, which of the following communication networks would be most appropriate?
Presented below are partial year-end financial statement data (000 omitted from dollar amounts) for companies A and B:
If company A has a quick ratio of 2:1, then it has an accounts receivable balance of:
When writing a business memorandum, the writer should choose a writing style that achieves all of the following except:
A manager has difficulty motivating staff to improve productivity, despite establishing a lucrative individual reward system. Which of the following is most likely the cause of the difficulty?
Which of the following price adjustment strategies encourages prompt payment?
Which of the following budgets must be prepared first?
One change control function that is required in client/server environments, but is not required in mainframe environments, is to ensure that:
Which of the following statements about COBIT is not true?
According to IIA guidance on IT auditing, which of the following would not be an area examined by the internal audit activity?